IBM Websphere Application Server Security component unspecified
| websphere-security-unspecified (33949) |
Description:
IBM WebSphere Application Server is vulnerable to an unspecified vulnerability in the Security component, which has an unknown impact and attack vector.
Platforms Affected:
- IBM, WebSphere Application Server 5.1.1
- IBM, WebSphere Application Server 5.1.1.1
- IBM, WebSphere Application Server 5.1.1.10
- IBM, WebSphere Application Server 5.1.1.11
- IBM, WebSphere Application Server 5.1.1.12
- IBM, WebSphere Application Server 5.1.1.13
- IBM, WebSphere Application Server 5.1.1.2
- IBM, WebSphere Application Server 5.1.1.3
- IBM, WebSphere Application Server 5.1.1.4
- IBM, WebSphere Application Server 5.1.1.5
- IBM, WebSphere Application Server 5.1.1.6
- IBM, WebSphere Application Server 5.1.1.7
- IBM, WebSphere Application Server 5.1.1.8
- IBM, WebSphere Application Server 5.1.1.9
- IBM, WebSphere Application Server 6.0.2.1
- IBM, WebSphere Application Server 6.0.2.11
- IBM, WebSphere Application Server 6.0.2.2
- IBM, WebSphere Application Server 6.0.2.3
- IBM, WebSphere Application Server 6.0.2.4
- IBM, WebSphere Application Server 6.0.2.5
- IBM, WebSphere Application Server 6.0.2.6
- IBM, WebSphere Application Server 6.0.2.7
- IBM, WebSphere Application Server 6.0.2.8
- IBM, WebSphere Application Server 6.0.2.9
Remedy:
Upgrade to the latest version of Websphere Application Server (Cumulative Fix 14 (5.1.1.14) or later), available from the Fix list for WebSphere Application Server Version 5.1.1. See References.
Consequences:
Other
References:
- Fix list for WebSphere Application Server Version 5.1.1, Cumulative Fix 14 (5.1.1.14) at http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg27006879#51114.
- CVE-2006-7198: Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/OS 601 before 6.0.2.13, has unknown impact and attack vectors, related to a Potential security exposure
- FrSIRT/ADV-2007-1553: IBM WebSphere Application Server Security Component Security Exposure Vulnerability
- SA25045: IBM WebSphere Application Server Unspecified Vulnerability
- SECTRACK ID: 1017976: IBM WebSphere Unspecified Flaw Has Unspecified Impact
Reported:
Apr 27, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
